I'm basically trying to block access to the device website from certain network ranges but allow all other traffic through.

the traffic comes into router A via fast0/0router A passes the traffic out to router B via fast0/1router A has the ACL being applied to as an inbound rule on fast0/1router B has the website only responding on the lo1 interface, which is advertised via OSPF

This is your problem. "In" and "Out" refer specifically to the interface's perspective. You can either change the application on FA0/1 to "out", or...better...apply the ACL to interface FA0/0 as an "in" rule.